Arbitrary Code Execution Vulnerability in Zed IDE by Zed Industries
CVE-2025-68432
What is CVE-2025-68432?
The Zed IDE, a popular code editor, contains a vulnerability that allows for arbitrary code execution through manipulated Language Server Protocol (LSP) configurations. If a user unwittingly opens a project containing a malicious settings.json file located in the project's .zed subdirectory, an attacker could execute arbitrary shell commands with the user's privileges. The vulnerability is triggered when the IDE loads these configurations upon opening the project file. To mitigate this risk, version 0.218.2-pre introduces a worktree trust mechanism, while users are advised to thoroughly examine the contents of any project settings file before opening projects in Zed.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
zed < 0.218.2-pre
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
